PT-2025-51850 · Unknown · Keepassxc-Browser

Justvraj04

·

Published

2025-12-17

·

Updated

2026-01-05

·

CVE-2025-65203

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions KeePassXC-Browser versions through 1.9.9.2
Description The software autofills or prompts users to fill stored credentials into documents rendered under a browser-enforced Content Security Policy (CSP) directive and iframe attribute sandbox. This allows attacker-controlled script within the sandboxed document to access populated form fields and potentially exfiltrate credentials.
Recommendations Update to a version later than 1.9.9.2.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-65203

Affected Products

Keepassxc-Browser